manifoldco / torus-cli

A secure, shared workspace for secrets
https://www.torus.sh
BSD 3-Clause "New" or "Revised" License
613 stars 32 forks source link

GPG Sign zips, rpms, debs #73

Open jbowes opened 7 years ago

jbowes commented 7 years ago

We should begin Signing the binary distributions posted to https://get.torus.sh, so their origin can be verified

ianlivingstone commented 6 years ago

If a user has apt configured such that it relies on trusted repositories it will error when they attempt to install torus from our published repositories!

ianlivingstone commented 6 years ago

A work around in the short term for apt is to use the --allow-unauthenticated, this is not ideal. Setting up proper release signing is high on our priority list!